AI Governance for Law Firms

What VLSB+C, LPLC and OAIC Actually Require
Consultants meeting with a client to discuss AI governance, risk, and compliance for law firms.

Legal Regulatory Compliance

Three regulators have now published guidance that directly affects how Australian law firms must govern the use of AI tools. This article maps what each regulator has said, what it means in practice, and what managing partners need to do to demonstrate compliance in 2026.

What Is Shadow AI in the Context of a Law Firm?

Most managing partners are aware that AI governance is becoming a regulatory concern. Fewer have had the time to work through what the relevant regulators have actually published, what those publications require in practice, and how the obligations interact.

This article does that work. It covers the three regulatory bodies with the most direct relevance to AI governance in Australian legal practice, the Victorian Legal Services Board and Commissioner (VLSB+C), the Legal Practitioners Liability Committee (LPLC), and the Office of the Australian Information Commissioner (OAIC), and maps their guidance to specific, actionable steps.

It is written for managing partners who have received regulator correspondence, who are preparing for a PI renewal conversation, or who simply want a plain-English account of where the obligations currently sit.

- FREE GUIDE -

AI Governance Checklist for Australian Businesses

Not sure if your organisation's AI use is putting sensitive data, compliance obligations, or client trust at risk?

Download our free AI Governance Checklist and assess your readiness across governance, data protection, staff behaviour, compliance, and incident response. Score your organisation in minutes and identify the gaps that need attention. 

✅ 30 practical assessment questions
✅ Board and leadership team friendly
✅ Identify Shadow AI and compliance risks
✅ Instant self-assessment scoring framework

Why Three Regulators, Not One

AI governance in a law firm sits at the intersection of professional conduct regulation, professional indemnity insurance, and privacy law. Each of those domains has a separate regulator with separate published guidance. None of the three has issued a single consolidated AI-specific standard. What they have done is publish guidance, enforcement actions, and commentary that, read together, create a clear picture of what is expected.

Understanding which regulator governs which obligation is the starting point.

The VLSB+C regulates professional conduct and practice standards for Victorian legal practitioners. It sets the framework within which the Australian Solicitors’ Conduct Rules operate, and it investigates complaints about breaches of professional obligations including confidentiality and client data handling.

The LPLC administers professional indemnity insurance for Victorian law firms and barristers. It assesses risk at the firm level and has the capacity to impose conditions on cover where a firm’s controls are found to be inadequate. Its guidance directly shapes what PI insurers will ask and what they will accept as evidence of adequate governance.

The OAIC administers the Privacy Act 1988 and the Australian Privacy Principles (APPs). It has enforcement authority over organisations that handle personal information, including law firms. Where a Shadow AI event results in client personal information being processed by an unapproved third-party platform, the OAIC’s framework is engaged.

What the VLSB+C Requires

The VLSB+C has not published an AI-specific policy. What it has done is enforce the professional conduct obligations that apply directly to AI-related data handling, and it has signalled through published guidance and regulatory commentary that technology governance is an area of increasing scrutiny.

The Confidentiality Obligation

The foundation is Rule 9 of the Australian Solicitors’ Conduct Rules (ASCR). Rule 9 requires that a lawyer must not disclose confidential client information unless the client has given informed consent, or disclosure is otherwise permitted under the Rules or by law.

When a fee earner or support staff member uses an unapproved AI tool to process client matter information, drafting correspondence, summarising documents, researching a matter, that information is transmitted to and processed by third-party infrastructure. The client has not consented. The firm has not assessed the tool. There is no data processing agreement. The disclosure is inadvertent, but it is a disclosure.

The VLSB+C has confirmed that inadvertent disclosure does not reduce a firm’s exposure under the ASCR. The obligation is to prevent disclosure, not merely to avoid deliberate disclosure.

Adequate Systems and Controls

Beyond confidentiality, the VLSB+C expects firms to maintain adequate systems and controls over the practice as a whole. This includes technology systems. A firm that has no documented AI governance policy, no assessment of which AI tools staff are using, and no technical controls to prevent unapproved use of AI with client data does not have adequate systems in place.

The VLSB+C does not prescribe a specific AI governance framework. What it does require is that a firm can demonstrate, if asked, that it has considered the risk, made a decision, documented that decision, and implemented controls proportionate to the firm’s size and the nature of its client data.

What the VLSB+C Expects in Practice

A firm seeking to satisfy VLSB+C expectations on AI governance should be able to demonstrate:

A documented AI governance policy that defines which tools are approved for use with client data, which are approved for internal use only, and which are prohibited.

A record that the policy has been communicated to all staff, including fee earners, paralegals, and support staff.

A process for assessing new AI tools before they are deployed with client data, including review of the vendor’s data processing terms, data residency commitments, and whether the tool uses client data for model training.

Technical controls that enforce the policy, rather than relying entirely on staff compliance.

For a broader view of the compliance frameworks relevant to legal practice, see Cybersecurity Frameworks Compared: Essential Eight vs ISO 27001 vs NIST.

What the LPLC Requires

The LPLC’s published guidance on technology risk has become progressively more specific as cyber incidents involving law firms have increased. Its guidance is not legally binding in the same way as the ASCR, but it directly shapes PI insurance conditions and is increasingly referenced in claims assessments.

The LPLC's Position on Technology Risk

The LPLC has stated explicitly that cyber incidents – including data leakage events – can give rise to professional indemnity claims where a firm’s internal controls are found to have been inadequate. It has identified inadequate technology governance as a contributing factor in a growing proportion of claims.

Shadow AI sits squarely in this category. An unsanctioned AI tool used by a fee earner to process client matter data is an uncontrolled data handling step. If that processing results in a disclosure – or if a client suffers loss because their information was exposed – the LPLC’s assessment of whether the firm had adequate controls will be a central factor in whether the claim is covered and on what terms.

What the LPLC Says About ChatGPT and Consumer AI Tools

The LPLC has not published a specific ChatGPT policy, but its published guidance on data handling and cyber risk applies directly. Consumer AI tools – including free-tier and personal-account versions of ChatGPT, Claude, Gemini, and similar platforms – do not offer the data processing agreements, data residency controls, or training data opt-outs that law firms need to use these tools with client data compliantly.

The LPLC’s position, read through its cyber guidance and claims data, is that a firm permitting staff to use consumer AI tools with client information without a documented assessment and policy is operating without adequate controls. That is a position that affects PI coverage.

PI Renewal and AI Governance Evidence

PI insurers working with the LPLC framework are increasingly asking about AI governance at renewal. Managing partners approaching renewal should expect questions about whether the firm has an AI governance policy, whether that policy has been communicated to staff, and whether technical controls are in place to enforce it.

A firm that cannot answer these questions with documented evidence is in a weaker position at renewal than one that can. For a detailed look at the five questions PI insurers are likely to ask and what evidence they will want, see The 5 Questions Your PI Insurer Will Ask About AI.

What the OAIC Requires

The Office of the Australian Information Commissioner administers the Privacy Act 1988 and the Australian Privacy Principles. Law firms that handle personal information – which includes virtually all client matter data, are subject to the APPs.

Australian Privacy Principles Most Relevant to AI Governance

Three APPs are directly engaged by Shadow AI use in a law firm.

APP 6 — Use and disclosure of personal information. APP 6 requires that an organisation must not use or disclose personal information for a purpose other than the primary purpose for which it was collected, unless an exception applies. When client personal information is entered into an AI tool and processed by that tool’s infrastructure — potentially including use for model training — the question of whether that use is consistent with the primary purpose of collection is engaged. In most cases, it is not.

APP 8 — Cross-border disclosure of personal information. Most consumer and enterprise AI platforms process data on infrastructure outside Australia. APP 8 requires that before disclosing personal information to an overseas recipient, the disclosing entity must take reasonable steps to ensure the recipient does not breach the APPs in relation to that information. An unapproved AI tool with no data processing agreement in place fails this requirement.

APP 11 — Security of personal information. APP 11 requires that an organisation take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. A firm that has no controls over which AI tools staff are using with client data, and no visibility into whether client personal information is being transmitted to external platforms, cannot demonstrate it has taken reasonable steps under APP 11.

The OAIC's Enforcement Posture

The OAIC has signalled an increasingly active enforcement posture following the Optus and Medibank breaches and the introduction of amended civil penalty provisions under the Privacy Act. While those cases involved large-scale breaches, the OAIC has made clear that it will assess whether organisations had reasonable controls in place, not merely whether a breach occurred.

For law firms, the practical implication is that a Shadow AI event affecting client personal information could attract OAIC investigation. The firm’s defence in that investigation will rest on whether it had documented and implemented reasonable controls. A firm with an AI governance policy, a tool assessment process, and technical enforcement controls is in a materially better position than one that does not.

Notifiable Data Breaches

Where a Shadow AI event results in a data breach that is likely to cause serious harm to affected individuals, the firm may be subject to the Notifiable Data Breaches (NDB) scheme. This requires notification to the OAIC and to affected individuals. The reputational and client relationship consequences of an NDB notification in a legal practice context are significant.

How the Three Frameworks Interact

The three regulators do not operate in isolation. A single Shadow AI event – a fee earner uploading a client document to an unapproved AI platform – can simultaneously engage all three.

The VLSB+C may investigate a complaint about breach of confidentiality under the ASCR. The LPLC may assess whether the firm had adequate controls when a resulting PI claim is made. The OAIC may investigate whether the firm took reasonable steps to protect personal information under APP 11 and whether an NDB notification is required.

Managing partners need to understand that these are not alternative obligations, they are concurrent. A single governance failure can attract regulatory scrutiny from all three directions at once.

The Practical Actions Firms Need to Take

Mapping the three regulatory frameworks to practical actions, the minimum a firm needs to demonstrate across all three is:

Document an AI governance policy. The policy must define approved and prohibited tools, set out what staff must not do with client information when using AI, and establish a process for assessing new tools before deployment. This satisfies the VLSB+C’s adequate systems requirement, gives the LPLC evidence of governance controls, and supports the firm’s APP 11 position.

Communicate the policy to all staff. A policy that exists but has not been communicated provides limited protection. The communication should be documented, and staff should be required to confirm they have read and understood it.

Assess AI tools before approving them for client data. For each tool the firm wants to approve, the assessment should cover: where data is processed and stored, whether the vendor’s terms include a data processing agreement, whether client data is used for model training, and whether the vendor’s data residency commitments are consistent with APP 8.

Implement technical controls. Policy and communication alone are not sufficient. Technical controls at the browser or network layer that identify unsanctioned AI access, prevent file uploads to unapproved platforms, and enforce allow and block lists convert a written policy into an enforceable governance framework.

Maintain an audit trail. The ability to demonstrate, if asked by any of the three regulators, that the firm assessed the risk, made documented decisions, communicated those decisions, and implemented controls is the foundation of a defensible position.

For a structured starting point covering all five of these areas, download the AI Governance Checklist for Law Firms.

What to Do This Week

If you are a managing partner reading this article and you do not have a documented AI governance policy in place, three actions are worth taking immediately.

First, ask your IT team or IT partner to identify which AI platforms are currently being accessed across the firm’s network. This is typically a one-day task and will give you a baseline picture of what is actually in use.

Second, issue a brief internal communication to all staff that client matter data must not be entered into any AI tool that has not been explicitly approved by the firm. This does not require a full policy to be in place — it is a holding position while you develop one.

Third, book a structured assessment. A Shadow AI discovery process maps what is in use, identifies the highest-risk behaviours, and produces a prioritised action plan. It takes a few hours of your IT team’s time and gives you a defensible starting point.

Book a Shadow AI Demo to see how KMTech identifies and governs unsanctioned AI use across a legal practice network.

Frequently Asked Questions

Does the VLSB+C require law firms to have AI governance controls?

The VLSB+C does not publish a specific AI governance standard, but its requirement that firms maintain adequate systems and controls over their practice applies directly to AI tool use. A firm that has no documented AI governance policy, no assessment of which tools staff are using with client data, and no technical controls to prevent unapproved use does not have adequate systems in place. The VLSB+C enforces the ASCR confidentiality obligations that are breached when client data is processed by unapproved AI platforms, and it expects firms to demonstrate that they have considered and managed this risk.

What does the LPLC say about ChatGPT?

The LPLC has not published a ChatGPT-specific policy, but its published guidance on data handling and technology risk applies directly to consumer AI tools. Consumer-tier accounts on platforms including ChatGPT, Claude, and Gemini do not provide the data processing agreements, data residency controls, or training data opt-outs that law firms require to use these tools with client data compliantly. The LPLC’s cyber guidance makes clear that permitting staff to use such tools with client information, without a documented assessment and policy in place, is operating without adequate controls — a position that affects PI coverage.

What Privacy Act obligations apply to AI use in a law firm?

Three Australian Privacy Principles are most directly engaged. APP 6 governs use and disclosure of personal information and is engaged when client data is processed by an AI tool for a purpose beyond its primary collection purpose. APP 8 governs cross-border disclosure and applies when AI platforms process data on overseas infrastructure without a compliant data processing agreement in place. APP 11 requires reasonable steps to protect personal information from misuse and unauthorised access, and a firm with no visibility or controls over AI tool use by staff cannot demonstrate compliance with this obligation.

Can a law firm be reported to the OAIC for Shadow AI?

Yes. Where a Shadow AI event results in client personal information being processed by an unapproved platform without consent, the OAIC’s enforcement framework is engaged. If the event is likely to cause serious harm to affected individuals, the firm may be required to notify both the OAIC and those individuals under the Notifiable Data Breaches scheme. The OAIC assesses whether organisations had reasonable controls in place, not merely whether a breach occurred, so a firm with no AI governance framework is in a weak position in any investigation.

What is the minimum AI governance a Victorian law firm needs?

At a minimum, a Victorian law firm needs a documented AI governance policy that defines approved and prohibited tools and sets out what staff must not do with client information. That policy must be communicated to all staff and supported by technical controls that enforce it. The firm also needs a process for assessing new AI tools before they are approved for use with client data, covering data residency, data processing agreements, and training data use. This minimum position addresses the VLSB+C’s adequate systems requirement, supports the LPLC’s evidence expectations at PI renewal, and provides the foundation for APP 11 compliance under the Privacy Act.

How do the VLSB+C, LPLC and OAIC obligations interact?

The three frameworks operate concurrently, not as alternatives. A single Shadow AI event – a fee earner uploading a client document to an unapproved AI platform, can simultaneously engage a VLSB+C investigation into breach of confidentiality under the ASCR, an LPLC assessment of whether the firm had adequate controls when a PI claim results, and an OAIC investigation into whether the firm took reasonable steps to protect personal information. Managing partners need to treat AI governance as satisfying obligations across all three frameworks at once, not as compliance with one regulator at a time.

Shadow AI & AI Governance Protection

For executives and technical leaders who need visibility and control

Your workforce is already using AI tools. The question is whether you can see it, govern it, and prevent data leakage.

If you're concerned about Shadow AI risk, AI governance gaps, or enabling AI safely without blocking innovation, we'll show you exactly what's happening in your organisation and how to protect it.

Request a demo to view real‑time visibility, protection, and governance controls

Author:  Bradley Kaine, CEO and Co-Founder, Kaine Mathrick Tech · Reading time: approximately 14 minutes

Bradley Kaine is CEO and co-founder of Kaine Mathrick Tech, a cyber-first managed IT services provider with offices across Melbourne, Sydney, Brisbane, and Hobart. He works with managing partners and firm principals across Australia to establish AI governance frameworks aligned to their professional obligations.

More on Web Filtering and Shadow AI from KMTech

Everything on this topic, in one place.

Last updated:

Related Stories

IT security professional reviewing a Managed Detection and Response (MDR) dashboard, illustrating KMTech's practical guide to 24/7 cyber threat monitoring

What is MDR? A Practical Guide to Managed Detection and Response

Learn what MDR cybersecurity is, how it works, and MDR vs EDR. See what an MDR service includes for Australian SMBs and mid‑market teams.

shadow ai

Shadow AI by the Numbers: Risk Data, Resources and Where to Start

Shadow AI, the unauthorised use of AI tools outside IT oversight, is already widespread in Australian businesses. This page brings together the data behind that risk.

Team meeting in an office setting with text overlay reading “Web Filtering and ISO 27001.”

Web Filtering and ISO 27001

This guide explains what ISO 27001 expects from web filtering and internet access controls, why legacy approaches often fall short, and how modern web filtering supports audit readiness, risk management, and ongoing compliance. Written for directors, executives, and IT leaders responsible for information security governance.

Want to be part of the crowd?

html